Encryption System with Dynamic Scheme Switching for Network Resilience
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing encryption technologies do not adequately address the need for robust security enhancements in networks, particularly in scenarios where encryption schemes are fixed and vulnerable to decryption by unauthorized devices, and existing methods like VPNs offer low security strength or incur high implementation costs.
Innovation Solution
An encryption system and method where a management device transmits encryption information to encryption and decryption devices, allowing dynamic switching of encryption schemes based on confidentiality and real-time performance requirements, using a separate transmission line to ensure secure communication even if the encryption scheme is compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a fixed encryption scheme is used, then implementation is simple and cost-effective, but security is vulnerable to decryption attacks
Solution Approach 1:
The patent implements dynamic encryption scheme switching where the encryption algorithm and parameters are changed at predetermined intervals. The encryption device receives encryption information from a management device and dynamically adjusts the encryption scheme based on timing information, transforming the static encryption approach into a dynamic one that adapts over time to maintain security.
Solution Approach 2:
The patent changes encryption parameters including the encryption algorithm type, key length, and initialization vectors at different time intervals. By varying these cryptographic parameters dynamically, the system enhances security strength without requiring a completely different encryption architecture.
2Reliability
If encryption information is transmitted via the same transmission line as communication data, then system complexity is reduced, but security is compromised if the transmission line is intercepted
Solution Approach 1:
The patent separates the transmission of encryption information from communication data by using different transmission lines. The management device transmits encryption information through a first transmission line while communication data is transmitted through a second transmission line, isolating the sensitive encryption parameters from potential interception on the data channel.
Solution Approach 2:
The patent introduces a management device as an intermediary that handles the secure distribution of encryption information to both encryption and decryption devices. This intermediary manages the encryption schemes and timing information, acting as a trusted mediator that coordinates the dynamic encryption switching without exposing the encryption parameters on the communication channel.
3Reliability
If dynamic encryption scheme switching is implemented, then security against decryption attacks is improved, but implementation complexity and cost increase
Solution Approach 1:
The patent implements periodic encryption scheme switching at predetermined time intervals. The management device transmits timing information that triggers both encryption and decryption devices to switch encryption schemes simultaneously, creating a periodic pattern that enhances security while maintaining manageable implementation complexity through regular, predictable changes.
Solution Approach 2:
The patent designs the encryption devices and management device with multi-functional capabilities to handle multiple encryption schemes and dynamic switching. By creating universal devices that can accommodate various encryption algorithms and parameters, the system reduces implementation costs compared to requiring separate dedicated hardware for each encryption scheme.
Data Source
AI summary
An encryption system includes a management device, an encryption device and a decryption device. The encryption device and the decryption device are connected to each other via a first transmission line serving as a physical transmission path, the management device is configured to transmit encryption information to the encryption device and the decryption device, the encryption information relating to an encryption scheme used in the encryption device and the decryption device, the encryption device is configured to generate encrypted data by performing an encryption process on communication data, based on the encryption information received from the management device, and to transmit the generated encrypted data to the decryption device via the first transmission line, and the decryption device is configured to perform a decryption process on the encrypted data received from the encryption device via the first transmission line, based on the encryption information received from the management device.


